Cybersecurity Watch Operations Subject Matter Expert IV
Job description
Title: Cybersecurity Watch Operations Subject Matter Expert IV
Location: Colorado Springs, CO
Clearance: TS/SCI with the ability to obtain and maintain a CI polygraph
Job Details:
-
Serve as the senior hands-on technical authority for SOC watch operations and a founding operational SME for the establishment and maturation of a new DoD SOC
-
Lead the most complex cyber defense investigations and incident-response activities and provide technical direction when scope, impact, evidence, or response options are uncertain
-
Perform advanced forensic and security analysis of digital information, host and network telemetry, firewall and IDS/IPS data, authentication activity, intrusion artifacts, and other relevant evidence
-
Establish and continuously improve investigative methodology, triage standards, severity and escalation criteria, evidence requirements, incident workflows, case-quality standards, and shift-turnover practices
-
Provide senior technical guidance to SOC management on watch readiness, investigative quality, operational risk, staffing proficiency, capability gaps, and response considerations
-
Serve as the highest-level operational escalation point for Cybersecurity Operations Analysts and mentor senior and developing personnel through complex investigations and exercises
-
Coordinate complex incidents with government stakeholders, incident response organizations, system owners, administrators, network/security engineers, and other agencies as required
-
Partner with cybersecurity engineering personnel to translate watch-operations requirements into actionable telemetry, SIEM/SOAR, network monitoring, firewall, endpoint, enrichment, and automation capabilities
-
Identify systemic visibility, detection, workflow, tooling, and analyst-proficiency gaps and develop recommendations to improve SOC effectiveness and enterprise security posture
-
Lead development and validation of SOPs, runbooks, incident-response playbooks, analyst qualification standards, training scenarios, exercises, and lessons-learned actions.
-
Conduct or direct proactive threat hunting and advanced analysis to identify malicious activity not detected by automated controls and to validate the effectiveness of existing defenses
-
Analyze trends across incidents and investigations and provide technical input to operational metrics, significant-activity reporting, leadership briefings, and defensive priorities
-
Apply network forensics, host analysis, malware-analysis concepts, vulnerability context, and threat-informed defense techniques as appropriate to complex investigations; advanced malware reverse engineering or penetration-testing experience is beneficial but not required
Requirements:
-
Bachelor's degree from an accredited institute in a technical discipline applicable to the position; an additional 4 years of may be substituted in lieu of a degree
-
Minimum of eight (8) years of relevant experience in addition to education level
-
Expert-level hands-on experience in SOC operations, cyber defense analysis, incident investigation, and incident response in complex enterprise environments
-
Demonstrated experience leading complex investigations while remaining technically hands-on.
-
Demonstrated ability to establish or materially improve SOC operating procedures, investigative standards, incident workflows, or analyst qualification/training programs
-
Strong knowledge of enterprise networking, network security monitoring, host/endpoint analysis, identity/authentication activity, incident response, and adversary TTPs
-
Experience collaborating with SIEM/SOAR, detection, network-security, endpoint, vulnerability, and other cybersecurity engineering teams
-
Experience helping establish, transform, or mature a SOC, CSIRT, or cyber defense capability is highly desired
-
Must possess current DoD 8570 IAT II or IAM II certification
-
Experience working in a DoD or IC environment
-
Current active TS/SCI clearance, with the ability to obtain and maintain a CI polygraph
Equal Opportunity Employer/Veteran/Disabled
More jobs at Invictusic
Collection Operations Manager
Invictusic· Washington, DC, USComputer Scientist
Invictusic· Washington, DC, USBiometrics Analyst
Invictusic· Washington, DC, USSoftware Programmer
Invictusic· Washington, DC, USComputer Scientist - Senior
Invictusic· Washington, DC, US
More jobs in Colorado Springs
Sales Consultant - Empire Homes
Precedent Land Company· Colorado Springs, CO, USA· $36kField / Install Technician - Colorado Springs, CO
Lifeway Mobility· Colorado Springs, CO, USATower - Top Hand
Ontivity· Colorado Springs, CO, USALaCroix Sparkling Water – MerchMx Representative
National Beverage· Colorado Springs, CO, USA2nd Shift Vault Teller- Colo Springs
Burroughs· Loomis Armored Colorado Springs, CO, 485 Elkton Dr, Colorado Springs, Colorado, United States of America· $38k